A company requires that IP packet data be inspected for invalid or malicious content. Which of the following approaches achieve this requirement? (Choose two.)
A.
Configure a proxy solution on Amazon EC2 and route all outbound VPC traffic through it. Perform inspection within proxy software on the EC2 instance.
B.
Configure the host-based agent on each EC2 instance within the VPC. Perform inspection within the host-based agent.
C.
Enable VPC Flow Logs for all subnets in the VPC. Perform inspection from the Flow Log data within Amazon CloudWatch Logs.
D.
Configure Elastic Load Balancing (ELB) access logs. Perform inspection from the log data within the ELB access log files.
E.
Configure the CloudWatch Logs agent on each EC2 instance within the VPC. Perform inspection from the log data within CloudWatch Logs.
C is incorrect. The VPC flow log stores multiple information about the packet, but it does not record the packet's content. Therefore these content cany be inspected.
D is incorrect. Same as C
E is incorrect. Same as C
AWS services cannot perform deep packet inspection (DPI) on IP packet data. This is because AWS follows strict policies that prioritize customer privacy and security. AWS services only process the IP headers, which contain the routing and addressing information for the packet, and not the packet payload, which contains the actual data being transmitted.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
BillyC
Highly Voted 3 years, 8 months agopolo
3 years, 8 months agoBillyC
3 years, 8 months agopolo
3 years, 8 months agoenthuguys
3 years, 7 months agojosellama2000
Highly Voted 3 years, 8 months agoBenah
Most Recent 1 year, 8 months agoyd_h
2 years, 2 months agogg12345
2 years, 6 months agodcasabona
2 years, 10 months agoryuhei
2 years, 10 months agoAppsec977
3 years agoTigerInTheCloud
3 years, 1 month agoRaySmith
3 years, 3 months agoRadhaghosh
3 years, 4 months agohk436
3 years, 7 months agoMikeclue
3 years, 7 months agosanjaym
3 years, 7 months agorocka1
3 years, 7 months agodevjava
3 years, 7 months agoAfricanCloudGuru
3 years, 7 months ago